Jeffrey Burt, Author at Security Boulevard https://securityboulevard.com/author/jeffrey-burt/ The Home of the Security Bloggers Network Fri, 29 Mar 2024 18:55:00 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Jeffrey Burt, Author at Security Boulevard https://securityboulevard.com/author/jeffrey-burt/ 32 32 133346385 ‘Darcula’ PhaaS Campaign Sinks Fangs into Victims https://securityboulevard.com/2024/03/darcula-phaas-campaign-sinks-fangs-into-victims/ Fri, 29 Mar 2024 18:55:00 +0000 https://securityboulevard.com/?p=2013455 phishing cybersecurity

A sprawling phishing-as-a-service (PhaaS) campaign that has been running since at least last summer is using more than 20,000 fake domains to target a wide range of organizations in more than 100 countries, illustrating the capabilities of an increasingly popular tool among threat actors. The unknown hackers are using a platform called “Darcula” (sic) that..

The post ‘Darcula’ PhaaS Campaign Sinks Fangs into Victims appeared first on Security Boulevard.

]]>
2013455
Google: Zero-Day Attacks Rise, Spyware and China are Dangers https://securityboulevard.com/2024/03/google-zero-day-attacks-rise-spyware-and-china-are-dangers/ Thu, 28 Mar 2024 16:57:17 +0000 https://securityboulevard.com/?p=2013310 vulnerability zero day

The number of zero-day vulnerabilities that are exploited jumped in 2023, with enterprises becoming a larger target and spyware vendors and China-backed cyberespionage groups playing an increasingly bigger role, according to Google cybersecurity experts. In a report this week, researchers with Google’s Threat Analysis Group (TAG) and its Mandiant business said they saw 97 zero-day..

The post Google: Zero-Day Attacks Rise, Spyware and China are Dangers appeared first on Security Boulevard.

]]>
2013310
Hundreds of Clusters Attacked Due to Unpatched Flaw in Ray AI Framework https://securityboulevard.com/2024/03/hundreds-of-clusters-attacked-due-to-unpatched-flaw-in-ray-ai-framework/ Thu, 28 Mar 2024 13:54:38 +0000 https://securityboulevard.com/?p=2013280 AI vulnerability

Thousands of servers running AI workloads are under attack by threat actors exploiting an unpatched vulnerability in the open-source Ray AI framework – widely used by such companies as OpenAI, Uber, Amazon, Netflix, and Cohere – giving hackers entrée to huge amounts of data and compute power. The campaign has been ongoing for at least..

The post Hundreds of Clusters Attacked Due to Unpatched Flaw in Ray AI Framework appeared first on Security Boulevard.

]]>
2013280
CISA, FBI Push Software Developers to Eliminate SQL Injection Flaws https://securityboulevard.com/2024/03/cisa-fbi-push-software-developers-to-eliminate-sql-injection-flaws/ Wed, 27 Mar 2024 13:32:41 +0000 https://securityboulevard.com/?p=2013153 SQL injection database

The federal government is putting pressure on software makers to ensure that their products don’t include SQL injection vulnerabilities, a longtime and ongoing threat that was put in the spotlight with last year’s far-reaching hack of Progress Software’s MOVEit managed file transfer tool. CISA and the FBI this week issued an alert urging tech manufacturer..

The post CISA, FBI Push Software Developers to Eliminate SQL Injection Flaws appeared first on Security Boulevard.

]]>
2013153
Complex Supply Chain Attack Targets GitHub Developers https://securityboulevard.com/2024/03/complex-supply-chain-attack-targets-github-developers/ Tue, 26 Mar 2024 18:42:46 +0000 https://securityboulevard.com/?p=2013043 supply chain, SBOM, cybersecurity, SLSA organizations third party attacks supply chain supply chain ransomware The Kill Chain Model

Unidentified threat actors used multiple tactics to launch a sophisticated software supply-chain campaign targeting developers on the GitHub platform, including members of the popular Top.gg community that includes more than 170,000 members. The attackers used a range of tactics and techniques, from leveraging stolen browser cookies to take over accounts to contributing malicious code with..

The post Complex Supply Chain Attack Targets GitHub Developers appeared first on Security Boulevard.

]]>
2013043
US, UK Accuse China of Years-Long Cyberespionage Campaign https://securityboulevard.com/2024/03/us-uk-accuse-china-of-years-long-cyberespionage-campaign/ Tue, 26 Mar 2024 14:22:21 +0000 https://securityboulevard.com/?p=2012992 China cyberespionage

The United States, the UK, and other countries this week accused a state-sponsored Chinese threat group of running a massive global hacking campaign for more than a decade that targeted political figures, journalists, businesses, political dissidents, and elections officials to steal information and spy on targets. U.S. Attorney Breon Peace called the work of the..

The post US, UK Accuse China of Years-Long Cyberespionage Campaign appeared first on Security Boulevard.

]]>
2012992
Tax Scams Ramping Up as the April 15 Deadline Approaches https://securityboulevard.com/2024/03/tax-scams-ramping-up-as-the-april-15-deadline-approaches/ Mon, 25 Mar 2024 12:49:52 +0000 https://securityboulevard.com/?p=2012842 Tax season scams

With the IRS deadline only weeks away, businesses and individuals are racing to get their taxes filed, and bad actors are doing what they can to keep pace with them. Both Microsoft and Malwarebytes in recent days have outlined various scams being used to steal sensitive information, drop malicious payloads, or make payments to fake..

The post Tax Scams Ramping Up as the April 15 Deadline Approaches appeared first on Security Boulevard.

]]>
2012842
RaaS Groups Go Recruiting in Wake of LockBit, BlackCat Takedowns https://securityboulevard.com/2024/03/raas-groups-go-recruiting-in-wake-of-lockbit-blackcat-takedowns/ Fri, 22 Mar 2024 18:47:26 +0000 https://securityboulevard.com/?p=2012750 ransomware RaaS

The effects of the recent high-profile disruptions of LockBit’s and BlackCat ransomware operations by law enforcement agencies are rippling through the dark web, with smaller threat gangs looking to scoop up the larger groups’ disaffected affiliates. Law enforcement agencies in the United States, the UK, and elsewhere in recent years have aggressively targeted the most..

The post RaaS Groups Go Recruiting in Wake of LockBit, BlackCat Takedowns appeared first on Security Boulevard.

]]>
2012750
CISA, NSA, Others Outline Security Steps Against Volt Typhoon https://securityboulevard.com/2024/03/cisa-nsa-others-outline-security-steps-against-volt-typhoon/ Thu, 21 Mar 2024 19:30:46 +0000 https://securityboulevard.com/?p=2012640 CISA China Volt Typhoon

Top cybersecurity agencies in the United States and other countries are again warning critical infrastructure companies about the “urgent risk” posed by Chinese state-sponsored threat group Volt Typhoon and are recommending steps to harden their protections. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and the FBI in an advisory reminded private..

The post CISA, NSA, Others Outline Security Steps Against Volt Typhoon appeared first on Security Boulevard.

]]>
2012640
Sentry, GitHub Use AI to Help Fix Coding Errors https://securityboulevard.com/2024/03/sentry-github-use-ai-to-help-fixing-coding-errors/ Thu, 21 Mar 2024 15:43:14 +0000 https://securityboulevard.com/?p=2012606 AI code fixing

Developers are getting more help detecting and addressing bugs in their code through new AI-based tools that Sentry.io and GitHub each introduced this week. Sentry unveiled the beta of Autofix, a feature that uses company’s machine learning and AI capabilities and is aimed at debugging errors in production by leveraging what the vendor knows about..

The post Sentry, GitHub Use AI to Help Fix Coding Errors appeared first on Security Boulevard.

]]>
2012606